ISO 9001 Internal Audit: A Checklist to Get Certified

The internal audit is the phase where it is decided whether the certification audit will be a formality or a race against the clock. It is also the one most organizations turn into a ritual: it gets scheduled, it gets done, a report is issued with two minor observations and everybody breathes easy.
That relief is the problem. An internal audit that finds nothing does not mean the system is fine: it means nobody looked where it hurts. When the certification body arrives, without that incentive, what was always there shows up.
What it is actually for
It has a single purpose: to find the problems while there is still room to correct them without a deadline overhead. It is not an exam to pass. It is the last cheap opportunity to fail.
That distinction changes the whole design. If the internal audit is framed as a demonstration that the system works, the auditor looks for confirming evidence. If it is framed as a search for faults, the auditor looks where evidence is weak. Only the second is useful.
Who can audit
The non-negotiable requirement is independence: nobody audits their own area. An operations manager does not audit operations, however well trained.
In small organizations this is solved with cross-auditing — quality audits operations, operations audits administration — or with an external auditor engaged only for that phase. What does not work is the same person who drafted the procedures verifying that they are followed.
The auditor also needs training in auditing, not just knowledge of the standard. Knowing what a clause requires is different from knowing how to obtain evidence that it is met.
How it is prepared
An annual programme, not a one-off event. The standard expects a programme covering all processes in scope across the cycle, prioritized by criticality and by the results of previous audits. A process that gave trouble is audited more often.
A plan per audit. Before each one: which processes, which clauses, who audits, who gets interviewed and when. It is sent in advance. Surprising the auditee adds nothing and does generate resistance.
A prepared checklist. Not a generic one downloaded from the internet, but one built from the organization's real procedures. Half the value of the exercise lives there.
What to review in each process
On the ground, four questions resolve most of it:
What does it say it does? Contrasted with the documented procedure.
What does it actually do? Observed and asked of whoever executes, not whoever supervises.
Where is the evidence? Concrete records, dated, showing the control operated. This is the question that generates the most findings.
What happened the last time it failed? If there is no record of any failure, either the process is perfect or nobody is recording.
Internal audit checklist
- The annual programme is approved and covers all processes in scope.
- Auditors are independent from the area they audit and trained in auditing.
- Each audit has a plan sent in advance.
- The checklist was built from your own procedures, not from a generic template.
- Whoever executes was interviewed, not only whoever supervises.
- Every finding cites objective evidence: document, record, date.
- Findings are classified as major nonconformity, minor, or opportunity for improvement.
- Every nonconformity has root cause analysis, not just correction.
- Corrective actions have an owner and a date.
- The effectiveness of actions closed in previous audits was verified.
- The results fed into the management review.
- There is a record of all of the above, available without hunting for it.
Point 10 is the one most often skipped and the first an experienced external auditor checks.
How to write a finding
A useful finding has three parts and no opinion:
The requirement. What the standard or your own procedure demands. The evidence. What was observed, with a concrete data point: document, number, date. The gap. Why what was observed does not meet the requirement.
"The area does not keep good control of documentation" is not a finding: it is a complaint. "Procedure PR-04 requires annual review of calibration records; equipment EQ-12 and EQ-15 show their last review in March 2024" is one.
The difference matters because root cause analysis depends on how it is written. A vague finding produces a vague corrective action.
What to do with nonconformities
The most widespread mistake is confusing correction with corrective action.
Correction is fixing the specific case: reviewing the two items with expired calibration. Corrective action is preventing recurrence: understanding why nobody detected the expiry and changing that.
Closing a nonconformity with only the correction guarantees it will reappear at the next audit. And the external auditor will notice, because they will review the history.
Root cause analysis does not need a sophisticated methodology. Asking "why" three times usually suffices. If the third answer points at a person, you have not reached the bottom; if it points at a process design decision, you have.
Common mistakes
Auditing against the standard rather than your own procedures. The standard says what must be achieved; the procedure says how your organization does it. You audit the second.
Looking for a pass. A report without relevant findings is a warning sign, not a success.
Auditing documents only. The document exists and is signed; the question is whether the process operates as stated.
Closing without verifying effectiveness. The action is marked complete without checking that it solved the problem.
Leaving it for the month before certification. With no time to correct, the internal audit becomes an expensive formality.
Where it fits in the Panamanian landscape
It helps to be clear about the institutional map. The DGNTI, part of the Ministry of Commerce and Industries, is "the national standardization body, which acts in the elaboration, adoption or adaptation of standards". The National Accreditation Council, also under the MICI, is "the National Accreditation Body of the Republic of Panama" and accredits conformity assessment bodies.
Neither of them audits your management system: that is done by the certification body you engage. Your internal audit is a requirement of the standard itself and the sole responsibility of the organization.
Where to start
If your first internal audit is close, spend more time building the checklist from your procedures than looking for templates. That is the difference between a useful exercise and a decorative one.
You can see how we work this phase in quality audit, and the full route to certification in ISO 9001 implementation. The wider practice is in quality systems.
Want a second opinion on your readiness? Book a free 15-minute assessment.

CEO, Grupo Alternative
Katherine González
PMP® | ISO 9001 Lead Auditor | MBA
I've spent 15 years helping companies in Latin America optimize their processes. I've seen how BPM transforms companies from within—reducing costs, accelerating growth, and improving the quality of life for teams.
Share this article